Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2904868 times)

0 Members and 8 Guests are viewing this topic.

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48596
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2475 on: March 29, 2013, 04:43:55 PM »
@ Bob
What is dangerous is the fact that the user has no way of identifying where the link leads to without clicking on the link. So there is an element of blind trust when using URL shortening methods.

I already use Long URL Mobile Expander add-on in FF, but it doesn't cover all or goo.gl being one such instance.

@ polonus
The 2nd link urlexpander, isn't as convenient as the Long URL Mobile Expander add-on as it appears to be on-line only - there is also a problem on the site any shortened url entered results in an application error. So not very good.
Google also checks the links it shortens for possible infections. :)  One of the reasons I use their service and not any of the others.
More information available at:
http://support.google.com/websearch/bin/answer.py?hl=en&answer=190768
« Last Edit: March 29, 2013, 04:45:57 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89132
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2476 on: March 29, 2013, 06:18:21 PM »
I just don't trust what I can't make an informed decision about and as for google checking the content, google searches, in particular image searches are rife with malware redirections (lots of instances seen in the forums). So excuse me if I don't trust google when it comes to cleaning their house.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48596
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2477 on: March 29, 2013, 06:29:09 PM »
I just don't trust what I can't make an informed decision about and as for google checking the content, google searches, in particular image searches are rife with malware redirections (lots of instances seen in the forums). So excuse me if I don't trust google when it comes to cleaning their house.
I don't pass along other peoples shortened link but, it's certainly easier to post the following:
http://goo.gl/VLXde
Instead of:
https://docs.google.com/document/d/1TCCX0R7AAF2WOxAMQ_kcun2nNnCPFAk2P4RBzFXSgds/edit
Since I know these are safe, the short link makes it easier for everyone.
Yes, you need to have some trust in the person who is passing this shortened link to you. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89132
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2478 on: March 29, 2013, 06:35:18 PM »
Yes its shorter, but so is A Google link and from that you can hover over the link and see where it leads.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2479 on: March 29, 2013, 06:51:06 PM »
And what if you're using a mobile device? One cannot hover over the link, so would the average user know the difference between the two?

People of my age group tend to disregard the url completely, possibly because there are no "preview urls" featured in mobile devices.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2480 on: March 29, 2013, 06:55:20 PM »
@DavidR,

Thanks for the additional info and the good advice. On Google Chrome browser I use  Long URL extension: https://chrome.google.com/webstore/detail/longurl/oldnehmjgfcannmkgkojafngdkhfkdpd
LongURL will replace shortened links using LongURL API This works fine for me,

@! Donovan, would use this also in your case as an apps: https://play.google.com/store/apps/details?id=com.tseng.longurlexp&hl=nl

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2481 on: March 29, 2013, 06:58:55 PM »
So conclusion here is to always use an expander for short URLs both on conventional comps and smartphones,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2482 on: March 31, 2013, 11:39:29 PM »
Hi malware sites that should fill the DNS sinkhole: http://www.malware-domains.com/
All files located here: http://www.malware-domains.com/files/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2483 on: April 01, 2013, 12:09:02 AM »
At least folks, do you hold these "immortals" blocked?

Immortals are long oustanding malware launching domains,
domains with a long lasting and continued history of spreading malcode,
or with the so-called "Long OVERDUE status".

An IDS list for them can be found here: http://www.autoshun.org/downloads/immortal_bhdns.rules
Or download the immortal_domains file from here: http://www.malware-domains.com/files/immortal_domains.zip

enjoy,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2484 on: April 03, 2013, 09:49:36 PM »
IP/hex/q.php hacks -> http://arstechnica.com/security/2013/04/exclusive-ongoing-malware-attack-targeting-apache-hijacks-20000-sites/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+arstechnica%2Ftechnology-lab+(Ars+Technica%3A+Technology+Lab)
Link article author: Aurich Lawson / Thinkstock
From the PHP manual to understand the attack better: http://php.net/manual/en/function.ip2long.php
The initial way the hack was performed is as yet not quite clear....

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2485 on: April 05, 2013, 11:37:34 AM »
Microsoft Security Bulletin Advance Notification for April 2013
http://technet.microsoft.com/en-us/security/bulletin/ms13-apr
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest

REDACTED

  • Guest
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2487 on: April 08, 2013, 09:02:57 PM »
Banking Trojan Carberp: An Epitaph?

https://blog.avast.com/2013/04/08/carberp_epitaph/

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #2489 on: April 12, 2013, 11:40:15 AM »
KB2839011 Released to Address Security Bulletin Update Issue
http://blogs.technet.com/b/msrc/archive/2013/04/11/kb2839011-released-to-address-security-bulletin-update-issue.aspx
http://support.microsoft.com/kb/2839011
There are some reports that TrendMicro is also affected by this security update issue.
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803